CVE-2017-0914

CWE-89SQL Injection5 documents5 sources
Severity
7.5HIGH
EPSS
0.2%
top 61.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 21
Latest updateMay 13

Description

Gitlab Community and Enterprise Editions version 10.1, 10.2, and 10.2.4 are vulnerable to a SQL injection in the MilestoneFinder component resulting in disclosure of all data in a GitLab instance's database.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

CVEListV5gitlab/gitlab_community_and_enterprise_editions10.2.0 - 10.2.5 Fixed in 10.2.6, 10.3.0 - 10.3.3 Fixed in 10.3.4, 9.1.0 - 10.1.5 Fixed in 10.1.6+2
NVDgitlab/gitlab9.4.09.5.10+3

🔴Vulnerability Details

2
GHSA
GHSA-fvhv-m54j-g33h: Gitlab Community and Enterprise Editions version 102022-05-13
CVEList
CVE-2017-0914: Gitlab Community and Enterprise Editions version 102018-03-21

📋Vendor Advisories

2
GitLab
CVE-2017-0914: Gitlab Community and Enterprise Editions version 10.1, 10.2, and 10.2.4 are vulnerable to a SQL injection in the MilestoneFinder component resulting i2018-03-21
Debian
CVE-2017-0914: gitlab - Gitlab Community and Enterprise Editions version 10.1, 10.2, and 10.2.4 are vuln...2017
CVE-2017-0914 (HIGH CVSS 7.5) | Gitlab Community and Enterprise Edi | cvebase.io